CVE-2023-45857
Aliases:GHSA-wf5p-g6vw-rhxx
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 08 Nov 2023, 00:00
Last modified:04 Sept 2024, 15:15
Vulnerability Summary
Overall Risk (default)
medium
36/100 CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.18% LOW
0% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
08 Nov 2023, 00:00
Published
Vulnerability first disclosed
04 Sept 2024, 15:15
Last Modified
Vulnerability information updated
Description
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.18%• Percentile: 39%
Techniques & Countermeasures
- CWE-352•Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Affected Systems
- axios•axios
1.5.1
- Npm•axios
≥ 1.0.0, < 1.6.0 | ≥ 0.8.1, < 0.28.0
References (13)
- https://github.com/axios/axios/issues/6006
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://nvd.nist.gov/vuln/detail/CVE-2023-45857
- https://github.com/axios/axios/issues/6022
- https://github.com/axios/axios/pull/6028
- https://github.com/axios/axios/pull/6091
- https://github.com/axios/axios/commit/2755df562b9c194fba6d8b609a383443f6a6e967
- https://github.com/axios/axios/commit/96ee232bd3ee4de2e657333d4d2191cd389e14d0
- https://github.com/axios/axios
- https://github.com/axios/axios/releases/tag/v0.28.0
- https://github.com/axios/axios/releases/tag/v1.6.0
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459